<?
$keyword = killInjection($_REQUEST['keyword']);
$sql="select * from tbl_order where code='$keyword'";
$result=mysql_query($sql,$conn);
$row=mysql_fetch_array($result);
if($row==0)
{
	echo("<h2><br>Không tìm thấy mã Order! Vui lòng nhập lại mã Order. Mã order là mã có 5 ký tự!");
	echo("<br><h3><a href=./>Trở về trang chủ </a>");
}
else
{
?>
<table border="1" cellpadding="2" bordercolor="#C0CECC" width="100%">
	<tr>
		<th width="71" class="title">Chi tiết</th>
		<th width="45" class="title">ID</th>
		<th width="77" class="title">Mã Order</th>
		<th width="57" class="title" >Tổng SP</th>    
        <th width="79" class="title">Tổng tiền</th>
		<th width="172" class="title" >Tên khách hàng</th>
    	<th width="107" class="title">Điện thoại</th>
        <th width="144" class="title">Email</th>
        <th width="145" class="title">Ngày đặt hàng</th>
	</tr>
  
<?
$keyword = killInjection($_REQUEST['keyword']);
$sql="select * from tbl_order where code='$keyword'";
$result=mysql_query($sql,$conn);
$i=0;
while($row=mysql_fetch_array($result)){	
?>
  
	<tr>
		<td bgcolor="<?=$color?>" class="smallfont" align="center">
			<input type="button" name="butDetail" value="Bên dưới" class="button" disabled="disabled"></td>
		<td bgcolor="<?=$color?>" align="center" class="smallfont"><?=$row['id']?></td>
		<td bgcolor="<?=$color?>" align="center"  style="background-color:#9CF"class="smallfont"><?=$row['code']?></td>
		<td bgcolor="<?=$color?>" align="center" class="smallfont">
		<?=$row['so_sanpham']?></td>
        <td bgcolor="<?=$color?>" align="center" class="smallfont"><?=number_format($row['tong_tien']*1000)?>
        (VNĐ)</td>
		<td bgcolor="<?=$color?>" class="smallfont"><?=$row['ten_kh']?></td>
        <td bgcolor="<?=$color?>" class="smallfont"><?=$row['dien_thoai']?></td>
        <td bgcolor="<?=$color?>" class="smallfont"><?=$row['email']?></td>
        <td bgcolor="<?=$color?>" class="smallfont" align="center"><?=$row['date_added']?></td>
	</tr>
<?
}
?>
</table>

<?
$sql="select * from tbl_order where code='$keyword'";
$result=mysql_query($sql,$conn);
$orderinfo=mysql_fetch_array($result);
?>

<table width="100%" border="0" cellpadding="2" cellspacing="0">
	<tr><td class="3" height="10"></td></tr>
	
	<tr>
		<td width="19%" class="smallfont" align="right">Họ và tên</td>
		<td width="2%" class="smallfont" align="center"></td>
		<td width="79%" class="smallfont"><b><?=$orderinfo['ten_kh']?></b></td>
	</tr>
	
	<tr>
		<td width="19%" class="smallfont" align="right">Phái</td>
		<td width="2%" class="smallfont" align="center"></td>
		<td width="79%" class="smallfont"><b><?=$orderinfo['phai']?></b></td>
	</tr>
	
	<tr>
		<td width="19%" class="smallfont" align="right">Địa chỉ</td>
		<td width="2%" class="smallfont" align="center"></td>
		<td width="79%" class="smallfont"><b><?=$orderinfo['dia_chi']?></b></td>
	</tr>
	
	<tr>
		<td width="19%" class="smallfont" align="right">Số điện thoại(!)</td>
		<td width="2%" class="smallfont" align="center"></td>
		<td width="79%" class="smallfont"><b><?=$orderinfo['dien_thoai']?></b></td>
	</tr>
	
	<tr>
		<td width="19%" class="smallfont" align="right">Email</td>
		<td width="2%" class="smallfont" align="center"></td>
		<td width="79%" class="smallfont"><b><?=$orderinfo['email']?></b></td>
	</tr>
	
	<tr>
		<td width="19%" class="smallfont" align="right">Tiêu đề</td>
		<td width="2%" class="smallfont" align="center"></td>
		<td width="79%" class="smallfont"><b><?=$orderinfo['tieu_de']?></b></td>
	</tr>
	
	<tr>
		<td width="19%" class="smallfont" align="right">Nội dung nhắn gởi</td>
		<td width="2%" class="smallfont" align="center"></td>
		<td width="79%" class="smallfont"><b><?=$orderinfo['noidung']?></b></td>
	</tr>
    
	<tr>
		<td width="19%" class="smallfont" align="right">Thời điểm giao hàng</td>
		<td width="2%" class="smallfont" align="center"></td>
		<td width="79%" class="smallfont"><b><?=dateFormat($orderinfo['td_gh'],"vn");?></b></td>
	</tr>
    
	<tr>
		<td width="19%" class="smallfont" align="right">Địa điểm giao hàng</td>
		<td width="2%" class="smallfont" align="center"></td>
		<td width="79%" class="smallfont"><b><?=$orderinfo['dd_gh']?></b></td>
	</tr>
    
	<tr>
		<td width="19%" class="smallfont" align="right">Thời điểm giao hàng</td>
		<td width="2%" class="smallfont" align="center"></td>
		<td width="79%" class="smallfont"><b><?=$orderinfo['tg_gh']?></b></td>
	</tr>
	
	<tr>
		<td width="19%" class="smallfont" align="right">Tổng tiền</td>
		<td width="2%" class="smallfont" align="center"></td>
		<td width="79%" class="smallfont" ><b><?=number_format($orderinfo['tong_tien']*1000);?>  </b> <font color="#FF0000">VNĐ </font></td>
	</tr>
	
    
	
	<tr><td class="3" height="10"></td></tr>
</table>

<table border="1" cellpadding="2" bordercolor="#C9C9C9" width="100%">
	<tr>
		<th width="18%" class="title">Mã hàng</th>
		<th width="20%" class="title">Tên SP</th>
		<th width="20%" class="title">Số lượng</th>
		<th width="18%" class="title">Đơn giá</th>
		<th width="24%" class="title">Thành tiền</th>    
	</tr>
  
<?
$orderId=$orderinfo['id'];

$sql="select * from tbl_order_detail where order_id=$orderId order by id";
$result=mysql_query($sql,$conn);
$i=0;
while($row=mysql_fetch_array($result)){
	$pro=getRecord("tbl_product","id=".$row['product_id']);
	$color = $i++%2 ? '#d5d5d5' : '#e5e5e5';
?>
  
	<tr>
		<td bgcolor="<?=$color?>" class="smallfont" align="center"><?=$pro['id']?></td>
		<td bgcolor="<?=$color?>" class="smallfont"><?=$pro['name']?></td>
		<td bgcolor="<?=$color?>" class="smallfont" align="center"><?=$row['quantity']?></td>
		<td bgcolor="<?=$color?>" class="smallfont" align="center"><?=number_format($row['price']*1000)?>&nbsp;<font color="#FF0000"><?=$currencyUnit?></font></td>
		<td bgcolor="<?=$color?>" class="smallfont" align="center"><?=number_format($row['quantity']*$row['price']*1000)?>&nbsp;<font color="#FF0000"><?=$currencyUnit?></font></td>
	</tr>
<?
}
?>
</table>
<input type="submit" value="Về trang chủ" name="btnHome"  onclick="javascript:window.location='./'" class="button">
</form>
<table width="100%">
	<tr><td height="10"></td></tr>
	<tr><td class="smallfont"><?='Tổng số hàng : <b>'.countRecord('tbl_order_detail','order_id='.$orderId).'</b>'?></td></tr>
</table>
<?

}?>